Slashdot Mirror


Google Researchers Say Software Alone Can't Mitigate Spectre Chip Flaws (siliconrepublic.com)

A group of researchers say that it will be difficult to avoid Spectre bugs in the future unless CPUs are dramatically overhauled. From a report: Google researchers say that software alone is not enough to prevent the exploitation of the Spectre flaws present in a variety of CPUs. The team of researchers -- including Ross McIlroy, Jaroslav Sevcik, Tobias Tebbi, Ben L Titzer and Toon Verwaest -- work on Chrome's V8 JavaScript engine. The researchers presented their findings in a paper distributed through ArXiv and came to the conclusion that all processors that perform speculative execution will always remain susceptible to various side-channel attacks, despite mitigations that may be discovered in future.

3 of 98 comments (clear)

  1. Re:Just always apply hardware access controls. by msauve · · Score: 4, Interesting

    But the summary claims "...all processors that perform speculative execution will always remain susceptible...". That's a blanket statement which covers all processors, existing or future.

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
  2. Bad time for Intel CPUs by bangular · · Score: 4, Interesting

    I'll be the first to admit this isn't my area of expertise. But after following these developments peripherally, I've been holding off buying a new desktop for awhile.

    It seems like Intel has bumbled this at every step. They've put out a lot of misinformation causing a lot consumer confusion. It seems like every time they exclaim "it's fixed!" researchers say that's not the case. I'm assuming at this point we're probably at least a couple of CPU generations away from Intel fixing this properly.

    On top of that, they've also been fighting the 10nm battle. More empty promises and missed deadlines on that front as well.

    When I compare my current aging Intel system to single thread performance of the latest generation, it just doesn't justify the cost. AMD claims Zen 2 will fix all their problems. If they deliver, I will probably switch back to AMD. Intel burned a lot of goodwill in the past few years.

  3. The irony by OneHundredAndTen · · Score: 3, Interesting

    And the much-maligned, all-but-dead Itanium is immune to Spectre. Fancy that.